Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in information exposure and denial of service.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-16842.json"